Table of Contents

Class ApplicationDataProtectionOptions

Namespace
ProjectTemplate.Web.Options
Assembly
ProjectTemplate.Web.dll

Options controlling the persistent ASP.NET Core Data Protection key ring.

public sealed class ApplicationDataProtectionOptions
Inheritance
ApplicationDataProtectionOptions
Inherited Members

Fields

SectionName

Configuration section name for Data Protection settings.

public const string SectionName = "ProjectTemplate:DataProtection"

Field Value

string

Properties

ApplicationName

Gets or sets the discriminator shared by application instances that must read the same protected payloads.

public string ApplicationName { get; set; }

Property Value

string

KeyEncryptionCertificatePassword

Gets or sets the password for KeyEncryptionCertificatePath.

public string? KeyEncryptionCertificatePassword { get; set; }

Property Value

string

Remarks

Supply this value from a secret store, environment variable, or mounted secret. Do not commit it to appsettings.json.

KeyEncryptionCertificatePath

Gets or sets the path to a PKCS#12 (.pfx) certificate used to encrypt key-ring files at rest. Relative paths are resolved from the content root.

public string? KeyEncryptionCertificatePath { get; set; }

Property Value

string

Remarks

When not set, key-ring files are written without application-level encryption. On Windows the framework protects them with DPAPI for the current user; on Linux and macOS they are written in plain text. The certificate must include its private key, and every replica must load the same certificate.

KeyRingPath

Gets or sets the persistent key-ring directory. Relative paths are resolved from the content root.

public string KeyRingPath { get; set; }

Property Value

string